Well its that time of the week in which I expose somebody (really hope this does not become a weekly “thing” XD )
We all know about Facebook and its REALLY confusing security setting’s.But sometimes I doubt whether they actually care about user privacy at all and this is one of those situations in which a persons lack of knowledge of keeping your account in the right setting’s will end up giving away your personal data.
I would consider my most “personal” data saved on Facebook to be my mobile number as it is somewhat of a bridge interlinking both my personal and online life and I would not like people I don’t want getting a hold of it. What if I tell you 98% 83 % of your phone numbers are not safe ? .. Only those lucky enough to stumble upon this setting and actually changing it are safe from the following (correction: http://www.twitlonger.com/show/jjpl97 )
Note:Even though this is technically a “0-day” ,I do not endorse criminal use of the following POC and leaked text
UPDATE: http://facebook-phone-crawler.googlecode.com/svn/trunk/facebook-hit.py [by TBorland] 7/10/2012
——————————————————————————————————————–
UPDATE 2 : Dead! All it takes is proof and a few day’s I guess. 9/10/2012
“Their throttling now.
Trying to lookup a 10k range no longer works. After… a few hundred (at most) you get logged you out with the following message.(It has been further reduced)
“Your account has been temporarily suspended We have detected some suspicious activity coming from this IP. As a security precaution, your account has been temporarily suspended.”
“Reactivation You will have to wait 24 hours to get back into your account.”" – A tester
It appears it’s the ‘figure out how the rate limit works’ game now. Wonder if it’s really as simple as this ip in x time instead of an actual rate limit.
——————————————————————————————————————–
First let me tell how I came across this.About a month ago I was just browsing FB on my FB mobile application and it had an option called “Find friends using contacts” ,what it does is that it compares the contact list from your phone to the FB database to see if you have any friends that are in your contacts but not on your Facebook account.
I also later figured out that simply “searching” a persons phone number(Including country code) will show you their account.Most of you will say “OH! I made my number as private so I am safe” NO YOU ARE NOT !
Let me show you how you are wrong ! Most of you would only have changed this (And this that’s the end of the line as far as your mobile is concerned)
Well FB managed to sneak in an another setting that still connects your phone number to you account.Its tucked away in your privacy setting’s
If you dint know this dont be hard on yourself ,even I dint know this setting before I found this out a month ago. I also questioned my friends and most of them did not know such a setting existed.(And MY friends are not the average joe’s ,they people from all over the tech industry)And VERY FEW knew about it. ( Also notice that the settings ends with “friends” ,WHY CANT I KEEP MY NUMBER TO MYSELF ? !!) Well my theory behind this is that,in order to get more users via phone numbers this setting is intentionally set at “everybody” by FB
So soon I mailed the Facebook security team telling them about a “hypothetical” way in which a person can obtain Username:Number using automated scripts. And Facebook just “meh’d it”
All further mails trying to explain the security implications were ignored !
And now I would also like to bring into attention the “Ineffectiveness” of Facebook’s security team.Not only do they not reply to mails properly some time’s they don’t bother replying at all . And there are even some cases in which a vulnerability you sent is fixed but you are not acknowledged or even notified that it is fixed.And this is not only my view but many other reputed security researchers. I asked them to send me their bitter experiences with Facebook
——————————————————————————————————————–
Harsha Vardhan Boppana
I have taken snip of my vuln before sending http://i45.tinypic.com/30uadxl.png It is fixed and didnt get reply and for following vulns facebook did accept that it targeted few users, therefore they did not accept some vulns . They r http://www.ehackingnews.com/2012/09/facebook-vulnerability-expose-personal-info.htmlI dont understand if its target’s only a few users, then Facebook wont care ?
DISCOVERED by RAFAY BALOCH:
http://www.rafayhackingarticles.net/2012/09/facebook-open-redirection-vulnerability.html ——————————————————————————————————————– Now getting back to the vulnerability.About a month later I realized that Facebook had taken NO action’s to prevent the attack that I had proposed was possible.
So I sent them an another mail telling them to “Fix” it such that automated searches cannot be made (Also to change the location of the settings so that people can actually see it and change it) Well look at the reply ! 
So I decided to make a very simple POC. It was just a macros script that read and saved the user names for a range of generated numbers,and send it to them Many of you might be wondering how I bypassed the “Rate limiting” by facebook. Well simple I used the mobile version ! THATS ALL!
Eg: http://m.facebook.com/search/?query=123456789
Replace”123456789″ with an actual mobile number .
Generate more such URL’s (with different numbers in the end) by using Exel and I was ready
NOTE: NOT ONCE IN THE LAST FOUR DAYS WAS I BLOCKED
Now I ran the script/macros for some time.What it does is that it open’s up the page and saves the data. I can quickly sort out the “No result found” from the positive results.
Also you can attack a certain mobile carrier or location if you know the specific area codes etc
(don’t ask me to provide it for you cause I don’t want people abusing it,any person worthy of it can make it himself/herself
)
Update: [have a look at Tyler’s script on the TOP its BETTER than my nooby script XD
I sent it to them again.THEY NEVER REPLIED !.. such is the state of the “security team” To show you the extent of such this vulnerability I will post a very small percentage of what I managed to download
Link to list:
http://privatepaste.com/3b9c229921
I also calculated that It would take a person with a large enough botnet (100k ) and a slightly better script(tylers will do the JOB) just a couple of days to download the ENTIRE Username:Phonenumber list of Facebook’s 600 million users who have mobile! Out of which at least 500 million would be vulnerable.
Connecting a persons phone number to a name is what every advertiser dreams of and these sort of list’s would fetch a LARGE price in the black market.And would also be a HUGE breach of privacy. So to protect yourself against this, change your settings to “My friends” and ask Facebook to provide an “Only me option” and make it such that it is the default setting for all users!.
To Facebook:
Facebook fix this soon!!.I wish it did not come to such a public exposure but you left me no choice.Also make sure that you reply to all mails and don’t ignore other security researchers!!
–Suriya
Media links(there are many more but thses ones I have checkd and approved):
http://datasecuritybreach.fr/actu/fuite-de-donnees-sur-facebook/ (thank Google for Google translate )
http://www.hotforsecurity.com/blog/facebook-privacy-is-goodbad-enough-just-flip-a-coin-3818.html
http://www.alertlogic.com/facebook-phone-abuse-the-tale-of-the-missing-rate-limit/
http://www.foxnews.com/tech/2012/10/10/facebook-lists-user-phone-numbers-for-all-to-see/
This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Unported License.

Pingback: Indagadores |Seguridad informatica |Seguridad en internet » Falla de seguridad en Facebook expone el número de usuarios de teléfonos
Pingback: Faulty Facebook Privacy Settings Expose User Phone Numbers, Researcher Says | CISSP 2 CISSP
Pingback: Fuite de données sur Facebook | Data Security Breach
Pingback: Facebook Privacy Is Good/Bad (Enough); Just Flip a Coin! | HOTforSecurity
Pingback: Facebook's phone search can be abused to find people's numbers, researchers say - Quick Download free stuff - Quick Download
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say | NEWS ONLINE
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say « Breaking News « Theory Report
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say | Tech Toys For Big Boys
Pingback: Facebook's phone search can be abused to find people's numbers, researchers say - IT Lounge
Pingback: Computer News » Facebook’s phone search can be abused to find people’s numbers, researchers say
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say | gintechno.com
Pingback: Facebook's phone search can be abused to find people's numbers, researchers say - itcenter-bg.com | itcenter-bg.com
Pingback: Facebook's phone search can be abused to find people's numbers, researchers say | Cell Phone Coupon
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say - International News
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say » My CMS
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say | CELL and COMPUTER
Pingback: Facebook's phone search can be abused to find people's numbers, researchers say | Daily World NewsDaily World News
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say | My Creative Directory
Pingback: Facebook Can Leak Your Data On Someone Else’s Phone — Privacy + Anonymity
Pingback: Me and Facebook (A C4utionary Tale) | Suriya’s Blog | facebook in the news
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say | errorwindow.info
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say- Tech Support by RAN Services in Augusta, GA
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say | Passcomms Laptop
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say | Love of Mac
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say | Price Gadget Reviews
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say | technewsforyou.com
Pingback: Facebook: Listen mit Profil-Telefonnummer-Zuweisungen leicht via mobile Seite erstellen - Servaholics
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers … - The Social Media News | The Social Media News
Pingback: Facebook's phone search can be abused to find people's numbers, researchers say | 投资手机
Pingback: Facebook: Lücke bei Telefonnummern-Suche
Pingback: Facebook’s phone search can be abused to find people’s numbers - Macworld Australia
Pingback: Phone Numbers Revealed | News from around the world
Pingback: Phone Numbers Revealed | Cell Phone Coupon
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say | Cotta Online
Pingback: Phone Numbers Revealed | 投资手机
Pingback: Facebook Develops “Extensive System” to Fix Phone Number Leakage Issue | CISSP 2 CISSP
Pingback: Facebook’s phone search can be abused to find people’s numbers | AbTak News
Pingback: BITLOG infotech hírek » Facebook mobilszámok
Pingback: Facebook phone number lookups now limited, but you should still tweak this privacy setting | BeachTechnology
Pingback: Facebook phone number lookups now limited, but you should still tweak this privacy setting | NEWS ONLINE
Pingback: Facebook phone number lookups now limited, but you should still tweak this privacy setting | METRO PC TECHS
Pingback: Facebook phone number lookups now limited, but you should still tweak this privacy setting | CELL and COMPUTER
Pingback: Facebook phone number lookups now limited, but you should still tweak this privacy setting | how to get the most from your gaming console
Pingback: Telefoonnummers op straat door lek in Facebook | Tech-nieuws
Pingback: Facebook phone number lookups now limited, but you should still tweak this privacy setting » Nottingham PC Repair
Pingback: Facebook phone number lookups now limited, but you should still tweak this privacy setting | Tech Toys For Big Boys
Pingback: Computer News » Facebook phone number lookups now limited, but you should still tweak this privacy setting
Pingback: Facebook phone number lookups now limited, but you should still tweak this privacy setting | TabletPCTrend.com
Pingback: Facebook Fixes Issue That Left Users’ Phone Numbers Vulnerable - AllFacebook
Pingback: Facebook phone number lookups now limited, but you should still tweak this privacy setting | Love of Mac
Pingback: Facebook Fixes Issue That Left Users’ Phone Numbers Vulnerable | FB Get
Pingback: Facebook Fixes Issue That Left Users’ Phone Numbers Vulnerable – Facebook Is Down
Pingback: Facebook phone number lookups now limited, but you should still tweak this privacy setting | Cell Phone Coupon
Pingback: Facebook phone number lookups now limited, but you should still tweak this privacy setting - Mobile App Shopper
Pingback: Facebook phone number lookups now limited, but you should still tweak this privacy setting | Price Gadget Reviews
Pingback: Telefoonnummers op straat door lek in Facebook | CISSP 2 CISSP
Pingback: How To Protect Your Phone Number On Facebook, Protect Your Privacy | Systems analysis in mathematics - key methods, different techniques
Pingback: Facebook phone number lookups now limited, but you should still tweak this privacy setting | Tux Doc
Pingback: Facebook phone number lookups now limited, but you should still tweak this privacy setting | My Creative Directory
Pingback: Facebook phone number lookups now limited, but you should still tweak this privacy setting
Pingback: Think Your Phone Number on Facebook is Private? Not Likely - The Social Media News | The Social Media News
Pingback: Think Your Phone Number on Facebook is Private? Not Likely - PC Magazine «
Pingback: Think Your Phone Number on Facebook is Private? Not Likely - PC Magazine |
Pingback: Facebook dicht lek telefoonnummers maar half | IclipsMedia
Pingback: Facebook phone number lookups now limited, but you should still tweak this privacy setting | 投资手机
Pingback: Facebook confirma fuga de datos | Partido Pirata
Pingback: Prevent Unauthorized Access to your Full Facebook Profile | What Is Privacy?
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say « OneTimeCode
Pingback: Facebook Giving Away Your #? | News from around the world
Pingback: 【注意】Facebookに大量の電話番号を取得できるセキュリティーホール発覚 - でじつべ
Pingback: Facebook to exclude phone numbers from reverse lookup – for users of two-factor authentication, anyway | Naked Security
Pingback: Facebook to exclude phone numbers from reverse lookup – for users of two » Cyber Crimes Unit | Cyber Crimes Unit
Pingback: Facebook’s phone search can be abused to find people’s numbers, researchers say | Roxx Studio Design - Graphic Design Services
Pingback: Anonymous
Pingback: Οι πλέον χρησιμοποιούμενες τεχνικές hacking ιστοσελίδων για το 2012
Pingback: Top Ten Web Hacking Techniques of 2012 - D0znpp blog
Pingback: Top Ten Web Hacking Techniques of 2012 | Phong Tử Blog - Cuộc Đời Lắm Gian Nan!
Pingback: Top Ten Web Hacking Techniques of 2012 | WhiteHat Security Blog
Pingback: CRONICAS DE UN HACKER… Las 10 mejores técnicas de hacking web en el 2012 | Factor Noticia
Pingback: Hacking for Beginners- Top Website Hacks « DECISION STATS